logo

WordPress Plugin Flaw Exposes 40,000+ Websites to Cyber Attack

ID: 334d2dbf-d2c1-53ee-aa65-8e836e7e1327

STIX ID: report--334d2dbf-d2c1-53ee-aa65-8e836e7e1327

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Divya

...
...

**Critical vulnerabilities in the WordPress Automatic (premium) plugin** allow unauthenticated arbitrary SQL execution and arbitrary file download/SSRF, potentially impacting over 40,000 sites; vendor patches (removing vulnerable file and adding nonce/validation checks) have been released and users are advised to update and use safe WordPress remote functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.